Back to Rule One Cinema

Privacy notice

Who operates the service

This notice explains the current beta’s data use. The responsible operator is Nkosinathi Shange. The service operates from South Africa. Email nkosinathishange502@gmail.com for support and privacy requests. A business contact address remains to be supplied before the notice is finalized.

Rule One Cinema is not an anonymous service. Sign-in is needed for its interactive features. Profile pictures, introductions, messages, posts and creative contributions are provided by you; many are optional.

Information processed

Sign-in uses an authenticated identifier and email from Supabase or ChatGPT. The app keeps a hash of the normalized email to map sign-in methods to one cinema profile. Email sign-in credentials are handled by Supabase; the app’s profile database does not store your password. Short-lived password-recovery grants expire after five minutes.

App records include display name, bio, film and music taste, optional pictures, community membership and role history, connection requests, direct and pair messages, posts and replies, uploaded stickers, quizzes, votes, writing, feedback, watched or hidden films, listening contributions, blocks and safety reports. Reports can retain a copy of the reported material for operator review.

Active app time is recorded for yearly recaps unless you disable it in Settings. A notification subscription stores a device push endpoint when enabled. Hosting and authentication services can also process technical request, device and security-log information.

Why information is used

Information is used to authenticate accounts, compare tastes, recommend films, operate communities and conversations, calculate quizzes and recaps, deliver opted-in notifications, handle reports and protect the service. No paid checkout, advertising-profile sale or advertising tracker is currently implemented.

Taste matching and recommendations use your saved preferences. They do not make employment, lending or other eligibility decisions. You can change your taste, hide films or decline a suggested connection.

Who can see it

Saved cinema profiles and public activities are visible to other signed-in members. Private community records are restricted by membership and permission checks; connection messages require an accepted connection, and pair conversations require the relevant pairing. The operator can review submitted safety reports.

Private access controls are not a promise of end-to-end encryption or a guarantee against recipients copying content. Do not upload confidential documents or sensitive personal details that you would not want the relevant audience to see. Your account email is shown privately in account settings and is not included in the public profile feed.

Service providers and international processing

The app uses Sites/Cloudflare for hosting, structured records and uploads, and Supabase for email authentication. ChatGPT handles its own sign-in accounts. Their infrastructure may process information outside your country; provider locations and appropriate transfer arrangements must be confirmed for the final notice.

Externally hosted images can reveal ordinary request information, such as IP address and browser information, to the image provider. Opening Apple Music, Spotify, TMDB, JustWatch or cinema links takes you to services with their own notices. Paystack is a proposed future payment provider; no live payment integration is currently collecting card details here.

Live sessions

Live sessions store session details, readiness, chat and short-lived connection signals. Microphone, camera and screen access begins only after you choose to enable it and grant browser permission. The app does not record or store call audio, video or shared-screen media. Other participants may still capture what they receive.

WebRTC transmits media between participants, with a network relay where configured. Direct connections can reveal network addresses to participants; Google STUN is used to establish connectivity. Any configured TURN relay processes connection and media traffic. Hosting stores connection signals, including network information, temporarily. Expired signals become unavailable after 60 seconds; expired session records and chat are eligible for cleanup 24 hours after expiry when another session is created. Profile and community deletion also removes applicable live-session records.

Cookies and device settings

Sign-in cookies maintain your session, and “Stay signed in” requests persistent sign-in. Local browser storage remembers settings such as viewing country, notification prompts, drum-sound preference and active-time preference. These settings are device-specific.

Device alerts require browser permission and can be disabled in Settings or browser controls. Optional in-app drum sounds can be muted. Operational alerts are separate from marketing; enabling message notifications does not sign you up for promotional emails.

Your controls and deletion limits

You can edit your profile, remove your own supported content, leave a community, withdraw table-read volunteering, block a member, disable device alerts and stop active-time recording. Creators can delete their communities.

Settings → Delete profile removes the cinema profile and associated app data handled by that feature, including owned communities. It does not close your ChatGPT account or automatically remove the Supabase authentication account. The email-to-profile hash and provider records may remain; infrastructure logs, backups or independently copied material may not be removed at the same time. A confirmed retention schedule is still required.

You may request access, correction or deletion of personal information, object to applicable processing and raise a privacy concern. Send these requests to nkosinathishange502@gmail.com. Avoid including passwords or recovery codes. South African users can also consult the Information Regulator at inforegulator.org.za.

Age, retention and future payments

An age policy and any processes needed for children’s participation have not yet been finalized. Do not advertise the beta as a service designed for children while those arrangements remain unresolved.

A final retention schedule must distinguish active records, expired recovery grants, authentication identities, safety evidence, operational logs and backups. This draft does not promise a deletion period that has not been implemented.

Before paid memberships launch, this notice must explain the payment provider, subscription identifiers, payment-status records, billing support and financial-record retention. Payment card collection should remain with the payment provider rather than the app’s profile database.